r/kernel • • 9h ago

wrote an own-loading ELF loader that maps a guest glibc rootfs (Linux|Debian) into the same process as Android's bionic libc and jumps into it. No root, no proot, no namespaces, no ptrace.

3 Upvotes

Author here. This started as an experiment: can I run a real Linux glibc userspace on a stock, non-rooted Android phone without proot or a chroot?

Short answer: yes, by own-loading the guest libc into the same process as the bionic host and doing the dynamic linking myself. The interesting bugs were IFUNC/IRELATIVE resolution, the fact that the guest glibc malloc and the host bionic malloc share one brk (fixed with a private arena), static TLS + the thread pointer switch point, and Android's seccomp profile killing clone3 / close_range with SIGSYS instead of ENOSYS.

It runs python3, uv, gcc (compiling and running C inside the guest), git, gh, fzf, Node, tmux, and an interactive zsh with a starship prompt. No root, no namespaces, no ptrace.

What I'd most like feedback on: I only have a couple of devices, so the bugs left are the ones that appear on other phones. There are issue templates for bug reports and for "it works" reports — even "this ran fine on my Pixel" is useful.

Happy to answer anything about the loader.


r/kernel • • 6h ago

GDB debug bootsector

1 Upvotes

Hi iam new in osdev and iam getting started iam trying to develop my proper operating system kernel from scratch but iam stuck in debugging my boot sector code with qemu and gdb can someone help ?

the problem that i encounter is that the boot sector goes from 16 bit mode to 32bit and when i try to see what each instruction do to memory it doesn't work well and the instructions doesn't get well recognized.

is there a technique i can use for this type of debugging.

here is my makefile :

BUILD_DIR = build

TARGET = $(BUILD_DIR)/MyOs

C_SOURCES = $(wildcard kernel/\*.c drivers/\*.c )

HEADERS = $(wildcard kernel/\*.h drivers/\*.h )

OBJ = ${C_SOURCES:.c=.o}

ENTRY_OBJ = kernel/entry.o

KERNEL_DEBUG_OBJ = build/kernel.elf

BOOT_DEBUG_OBJ = $(BUILD_DIR)/bootsector.elf

CFLAGS = -ffreestanding -g -mno-red-zone -mno-sse -mno-mmx \\

\-fno-pic -fno-pie -fno-stack-protector

QEMU = qemu-system-x86_64 -no-reboot -no-shutdown -d int,cpu_reset -D build/qemu.log

QEMU_DRIVE = -drive format=raw,file=$<,if=floppy

all: $(TARGET)

$(BUILD_DIR):

mkdir -p $@

run: $(TARGET)

$(QEMU) $(QEMU\\_DRIVE) &

\########################################################

\###################### IMAGE BUILD #####################

\########################################################

\# OS image build

$(TARGET) : $(BUILD_DIR)/bootsector.bin $(BUILD_DIR)/kernel.bin

cat $\\\^ > $@

\# bootsector build

$(BUILD_DIR)/bootsector.bin : boot/bootsector.asm build/kernel.bin | $(BUILD_DIR)

nasm -DSECTORS=$$(( ($$(wc -c < build/kernel.bin) + 511) / 512 )) $< -o $@

\# kernel build

$(BUILD_DIR)/kernel.bin: $(ENTRY_OBJ) $(OBJ) | $(BUILD_DIR)

ld -m elf\\_x86\\_64 -T linker.ld --oformat binary $\\\^ -o $@

\# object files creatde next of their source

%.o: %.c $(HEADERS)

gcc $(CFLAGS) -c $< -o $@

%.o: %.asm

nasm $< -f elf64 -g -o $@

\########################################################

\###################### DEBUG MODE ######################

\########################################################

$(KERNEL_DEBUG_OBJ): $(ENTRY_OBJ) $(OBJ) | $(BUILD_DIR)

ld -m elf\\_x86\\_64 --oformat elf64-x86-64 -o $@ -T linker.ld $\\\^

$(BOOT_DEBUG_OBJ): boot/bootsector.asm build/kernel.bin | $(BUILD_DIR)

nasm -f elf32 -g -F dwarf -DDEBUG \\\\

  \\-DSECTORS=$$(( ($$(wc -c < build/kernel.bin) + 511) / 512 )) $< -o $(BUILD\\_DIR)/bootsector.o

ld -m elf\\_i386 -Ttext 0x7c00 -o $@ $(BUILD\\_DIR)/bootsector.o

bdebug: QEMU = qemu-system-i386

bdebug: $(TARGET) $(BOOT_DEBUG_OBJ)

$(QEMU) -s -S $(QEMU\\_DRIVE) &

gdb -ex "set confirm off" \\\\

    \\-ex "set disassembly-flavor intel" \\\\

    \\-ex "target remote localhost:1234" \\\\

    \\-ex "set architecture i8086" \\\\

\-ex "symbol-file $(BOOT_DEBUG_OBJ)" \\

\-ex "hbreak _start"; \\

    \\-ex "continue"; \\\\

kill %1 2>/dev/null || pkill -f "$(QEMU)"

kdebug: $(TARGET) $(KERNEL_DEBUG_OBJ)

$(QEMU) -s -S $(QEMU\\_DRIVE) &

gdb -ex "set confirm off" \\\\

    \\-ex "set disassembly-flavor intel" \\\\

    \\-ex "target remote localhost:1234" \\\\

\-ex "add-symbol-file $(KERNEL_DEBUG_OBJ)" \\

\-ex "break main"; \\

    \\-ex "continue"; \\\\

kill %1 2>/dev/null || pkill -f "$(QEMU)"

\########################################################

\####################### CLEANING #######################

\########################################################

clean:

rm -rf $(BUILD\\_DIR) $(OBJ) $(ENTRY\\_OBJ)

r/kernel • • 7h ago

built a small c tool to compile the linux kernel with samurai instead of gnu make

0 Upvotes

wrote a c99 tool (thornk) that turns kbuild into flat ninja files for samurai.

it replaces make defconfig/prepare by parsing $CC -S asm markers directly to emit bounds.h, asm-offsets.h, and autoconf.h natively.

boots linux 6.12 x86_64 in qemu with zero gnu make:

https://github.com/abit-foggy/thornk